Skip to main content
mySites.guru
5+ live

Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE

CVE-2026-74251Critical

Phoca Cart (com_phocacart) below 6.1.7 - Unauthenticated SQL Injection in the product filter

Phoca Cart builds the product filter query by concatenating the a (attribute) and s (specification) request parameters straight into the WHERE clause inside hand-written quotes, instead of passing them through the database quoting. The front-end product listing model reads both parameters from the request using the Joomla array filter, which does not sanitise the values inside the array, so any anonymous visitor can reach the injection on a public product or category listing page with no account and no token. Update to Phoca Cart 6.1.7 or later. If this site runs Joomla 5 rather than Joomla 6, the Joomla updater will NOT offer 6.1.7: the update feed maps Joomla 5 to the 5.x release and 5.2.4 sorts lower than the installed 6.x version, so the update screen reports nothing to update. Download the 6.1.7 package from GitHub or phoca.cz and install it through Extensions, Install, Upload Package File. The Joomla CNA published CVE-2026-74251 for this flaw on 16 August 2026, scoring it CVSS 4.0 9.3 Critical (CWE-89). The record states the affected range as 5.0.0-6.1.16; there is no Phoca Cart 6.1.16, the highest release on the 6.x line is 6.1.7 and that is the build containing the fix, so read the upper bound as 6.1.6.

Affected versions: ≥ 6.0.0 and < 6.1.7

Official record: cve.org · NVD

Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Phoca Cart - Phoca Cart (com_phocacart) below 5.2.4 - Unauthenticated SQL Injection in the product filter

Phoca Cart builds the product filter query by concatenating the a (attribute) and s (specification) request parameters straight into the WHERE clause inside hand-written quotes, instead of passing them through the database quoting. The front-end product listing model reads both parameters from the request using the Joomla array filter, which does not sanitise the values inside the array, so any anonymous visitor can reach the injection on a public product or category listing page with no account and no token. Update to Phoca Cart 5.2.4 or later on the Joomla 5 line. Note that Joomla 5 sites running a Phoca Cart 6.x version will NOT be offered this fix by the Joomla updater, because the update feed maps Joomla 5 to the 5.x release and 5.2.4 sorts lower than the installed 6.x version, so the update screen shows nothing: those sites need the 6.1.7 package installed manually. The Joomla CNA published CVE-2026-74251 for this flaw on 16 August 2026, scoring it CVSS 4.0 9.3 Critical (CWE-89).

Affected versions: ≥ 5.0.0 and < 5.2.4

Full advisory: our disclosure post

Phoca Cart - Phoca Cart (com_phocacart) 4.x - Unauthenticated SQL Injection in the product filter, no fixed release

Phoca Cart builds the product filter query by concatenating the a (attribute) and s (specification) request parameters straight into the WHERE clause inside hand-written quotes, instead of passing them through the database quoting. The front-end product listing model reads both parameters from the request using the Joomla array filter, which does not sanitise the values inside the array, so any anonymous visitor can reach the injection on a public product or category listing page with no account and no token. Phoca fixed this on 16 August 2026 in 5.2.4 (Joomla 5 line) and 6.1.7 (Joomla 6 line). The Joomla 4 line was NOT patched: 4.0.12 is the newest 4.x release and the newest version offered to Joomla 4 sites by the update feed, and it still contains the identical vulnerable code, so every 4.x version is affected with no fixed release available. There is no in-branch remedy. Migrate the site to Joomla 5 or 6 and install the patched Phoca Cart, or remove the extension. The Joomla CNA published CVE-2026-74251 for this flaw on 16 August 2026, scoring it CVSS 4.0 9.3 Critical (CWE-89). The published affected range starts at 5.0.0, so it does not formally cover the 4.x branch, but we extracted 4.0.12 and confirmed the identical unpatched code, which is why this rule flags it.

Affected versions: ≥ 4.0.0 and < 5.0.0

Full advisory: our disclosure post

Phoca Cart - Phoca Cart (com_phocacart) 3.x - Unauthenticated SQL Injection in the product filter, no fixed release

Phoca Cart builds the product filter query by concatenating the a (attribute) and s (specification) request parameters straight into the WHERE clause inside hand-written quotes, instead of passing them through the database quoting. The front-end product listing model reads both parameters from the request using the Joomla array filter, which does not sanitise the values inside the array, so any anonymous visitor can reach the injection on a public product or category listing page with no account and no token. Phoca fixed this on 16 August 2026 in 5.2.4 (Joomla 5 line) and 6.1.7 (Joomla 6 line). The Joomla 3 line was NOT patched: 3.5.8 is the newest 3.x release and it still contains the identical vulnerable code, so every 3.x version is affected with no fixed release available. There is no in-branch remedy. Migrate the site to a supported Joomla version and install the patched Phoca Cart, or remove the extension. The Joomla CNA published CVE-2026-74251 for this flaw on 16 August 2026, scoring it CVSS 4.0 9.3 Critical (CWE-89). The published affected range starts at 5.0.0, so it does not formally cover the 3.x branch, but we extracted 3.5.8 and confirmed the identical unpatched code, which is why this rule flags it.

Affected versions: ≥ 3.0.0 and < 4.0.0

Full advisory: our disclosure post

Our disclosure post

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 25 August 2026.